🇺🇸 Certified Information Security Manager (CISM) · subject

Certified Information Security Manager (CISM) Information Security Risk Response and Reporting Syllabus

Every chapter and topic of Information Security Risk Response and Reporting examined in Certified Information Security Manager (CISM) — 3 chapters, 9 topics and 18 sub-topics, plus 51 flashcards written against it.

3Chapters
9Topics
18Sub-topics
~10hEst. first pass
13%Of Certified Information Security Manager (CISM)
51Flashcards

Information Security Risk Response and Reporting syllabus — full chapter and topic list

Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Security Risk Response and Reporting in Certified Information Security Manager (CISM), not a summary of it.

  1. Risk Treatment and Control Selection

    3 topics
    • Risk Treatment Options
      • Mitigate, transfer, avoid, and accept
      • Cost-effectiveness of controls
    • Control Selection and Design
      • Preventive, detective, and corrective controls
      • Control baselines and tailoring
    • Risk Ownership and Acceptance
      • Formal risk acceptance and sign-off
      • Exception and waiver management
  2. Risk Monitoring and Communication

    3 topics
    • Ongoing Risk Monitoring
      • Key risk indicators and thresholds
      • Continuous control monitoring
    • Risk Register Management
      • Maintaining and updating the register
      • Tracking remediation and timelines
    • Risk Reporting and Escalation
      • Stakeholder-tailored risk reporting
      • Escalation triggers and pathways
  3. Integrating Risk into Operations

    3 topics
    • Risk in the System Development Lifecycle
      • Security requirements and design reviews
      • Change and release risk evaluation
    • Third-Party and Cloud Risk
      • Vendor due diligence and assessments
      • Shared responsibility in cloud environments
    • Risk Awareness and Culture
      • Embedding risk culture across teams
      • Role-based risk education

Information Security Risk Response and Reporting flashcards for Certified Information Security Manager (CISM)

25 of 51 cards from the Information Security Risk Response and Reporting deck — real questions with worked answers.

  1. What are the four primary risk treatment (risk response) options?

    Mitigate (reduce/modify), Transfer (share), Avoid (terminate), and Accept (retain) the risk.

  2. In risk treatment, what does 'risk avoidance' mean?

    Eliminating the risk entirely by not engaging in the activity, discontinuing it, or removing the asset/condition that creates the exposure.

  3. What is 'risk transfer' (risk sharing), and what are common examples?

    Shifting some or all of a risk's impact to a third party. Examples: purchasing insurance and outsourcing a function to a vendor. Liability/accountability typically remains with the organization.

  4. What is 'risk mitigation' in risk treatment?

    Reducing the likelihood and/or impact of a risk to an acceptable level by implementing controls or other measures.

  5. What is 'risk acceptance' (risk retention)?

    A conscious, documented decision to take no action and live with a risk because it falls within risk appetite/tolerance or because treatment costs exceed the benefit.

  6. What is 'residual risk'?

    The risk that remains after controls/treatment have been applied. It must be within risk tolerance or formally accepted by the risk owner.

  7. What is the difference between inherent risk and residual risk?

    Inherent risk is the risk level before any controls are applied; residual risk is the risk that remains after controls are implemented.

  8. How should an organization choose among risk treatment options?

    By comparing the cost of treatment against the expected reduction in risk (cost-benefit analysis), and selecting the option that brings residual risk within risk appetite at justifiable cost.

  9. What is the formula for single loss expectancy (SLE)?

    SLE = Asset Value (AV) × Exposure Factor (EF), where EF is the percentage of asset value lost in a single event.

  10. What is the formula for annualized loss expectancy (ALE)?

    ALE = SLE × ARO (Annualized Rate of Occurrence). It estimates expected annual loss from a risk.

  11. How is the cost-benefit value of a control calculated using ALE?

    Value of control = (ALE before control) − (ALE after control) − (annual cost of the control). A positive value indicates the control is cost-justified.

  12. What three control types are classified by function (action timing)?

    Preventive (stop incidents before they occur), Detective (identify incidents in progress/after), and Corrective (restore/respond after an incident).

  13. Name the control categories classified by nature of implementation.

    Administrative/Managerial (policies, procedures, training), Technical/Logical (firewalls, encryption, access controls), and Physical (locks, guards, fences).

  14. What is a 'compensating control'?

    An alternative control implemented when the primary/required control is not feasible, providing comparable protection to satisfy the control objective.

  15. What is a 'deterrent control'? Give an example.

    A control that discourages a threat actor from acting. Examples: warning banners, visible CCTV, and security guards.

  16. What principle states controls should be layered so failure of one does not cause total compromise?

    Defense in depth (layered security), using multiple, overlapping controls.

  17. What is the difference between control effectiveness and control efficiency?

    Effectiveness measures whether a control actually achieves its objective (reduces risk); efficiency measures whether it does so at reasonable/optimal cost.

  18. What is a Key Control Indicator (KCI)?

    A metric that measures how well a control is performing (its effectiveness), helping detect control degradation before risk materializes.

  19. When designing controls, why must the control cost not exceed the value of the asset or expected loss?

    Because security must be cost-effective; spending more on a control than the potential loss or asset value is not economically justified.

  20. Who is the 'risk owner' and what is their core responsibility?

    The individual (usually a business/process owner with authority) accountable for a specific risk, responsible for deciding and approving its treatment and accepting residual risk.

  21. Why should business/process owners, not the security team, own and accept risks?

    Because they own the assets and have the authority and budget to make business-impact decisions; security advises but does not own business risk.

  22. What must accompany a formal risk acceptance decision?

    Documented justification, the approving risk owner's authority/sign-off, the residual risk level, and a defined review/expiration date.

  23. What is 'risk appetite'?

    The amount and type of risk an organization is willing to pursue or retain to achieve its objectives, set by senior management/board.

  24. What is 'risk tolerance'?

    The acceptable level of variation (deviation) around risk appetite for a specific risk or objective — the practical threshold/boundary for retaining risk.

  25. What is the difference between risk appetite and risk tolerance?

    Risk appetite is the broad, strategic level of risk the organization is willing to take; risk tolerance is the specific, often quantified, acceptable deviation at the operational level.

See more Information Security Risk Response and Reporting flashcards →

Planning Information Security Risk Response and Reporting for Certified Information Security Manager (CISM)

Information Security Risk Response and Reporting is about 13% of the Certified Information Security Manager (CISM) syllabus by topic count — 9 of 68 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 10 hours.

The heaviest chapters are Risk Treatment and Control Selection (3 topics), Risk Monitoring and Communication (3 topics), Integrating Risk into Operations (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.

Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.

Information Security Risk Response and Reporting (Certified Information Security Manager (CISM)) FAQ

What is in the Certified Information Security Manager (CISM) Information Security Risk Response and Reporting syllabus?

Information Security Risk Response and Reporting is split into 3 chapters — Risk Treatment and Control Selection, Risk Monitoring and Communication and Integrating Risk into Operations, containing 9 topics and 18 sub-topics in total.

How many chapters are there in Information Security Risk Response and Reporting for Certified Information Security Manager (CISM)?

3 chapters. Information Security Risk Response and Reporting accounts for about 13% of the topics in the whole Certified Information Security Manager (CISM) syllabus (9 of 68).

How long should I spend on Information Security Risk Response and Reporting for Certified Information Security Manager (CISM)?

Budget around 10 hours for a first pass through Information Security Risk Response and Reporting — about 45 minutes per topic plus 12 minutes per sub-topic across its 9 topics. Add revision cycles on top.

Are there flashcards for Certified Information Security Manager (CISM) Information Security Risk Response and Reporting?

Yes — a 51-card Information Security Risk Response and Reporting deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.